CVE-2017-2803: Corel Coreldraw Photo Paint x8

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A remote out of bound write vulnerability exists in the TIFF parsing functionality of Core PHOTO-PAINT X8 version 18.1.0.661. A specially crafted TIFF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific TIFF file to trigger this vulnerability. This vulnerability only exists in the 64-bit version.

Affected products

  • Corel Coreldraw Photo Paint x8: version 18.1.0.661 only

Published 2018-04-24. Last modified 2026-06-17.